|
|
Info |
Last Modified |
| 8 months ago |
|
|
|
|
Description |
Argosoft Mail Server Pro contains a flaw that allows a remote attacker to view arbitrary files on mail server outside of the web path. The issue is due to the msg script not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the "UIDL" variable. An authenticated attacker can view messages of other users, configuration files or other text files on the mail server.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Information Disclosure,
Input Manipulation
Impact:
Loss of Confidentiality
Exploit:
Exploit Unknown
OSVDB:
Web Related
|
|
Solution |
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
|
|
Products |
|
ArGoSoft Mail Server Pro
 |
1.8.7.6 |
1.8.7.7 |
|
|
|
|
|
|
Credit |
- ShineShadow - ss_contacts
hotmail.com -
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|